8 days ago
Doha, QatarMid Level
Responsibilities
- Conduct penetration tests on web applications, mobile applications, APIs, and thick-client applications.
- Prepare detailed reports with actionable remediation recommendations.
- Implement and manage SAST, DAST, and SCA security scanning tools.
- Perform threat modeling and provide guidance on mitigating application security risks.
- Review application code for security vulnerabilities and recommend remediation.
- Develop and deliver application security training sessions and workshops.
- Evaluate and recommend application security testing and monitoring tools.
- Create and maintain documentation for security assessments, vulnerability management, and security policies.
Requirements
- Bachelor’s or college degree in Computer Science, Information Security, or a related field.
- At least 2 years of experience in application security, software development, or a related field.
- Proficiency with Burp Suite; familiarity with Fortify, SonarQube, and Postman is preferred.
- Strong understanding of secure coding practices and experience with at least one programming language.
- In-depth knowledge of application security principles and practices.
- Familiarity with OWASP Top 10, ASVS, MASVS, WSTG, and MSTG frameworks and guidelines.
- Relevant certifications such as BCSP, OSWA, OSWE, eWPT, eWPTX, or SEC542 are highly desirable.
- Familiarity with DevSecOps practices and CI/CD pipelines is a plus.
Tech Stack
PostmanSonarQube
